Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add artemnovichkov/skills/plugin install sdlcWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/artemnovichkov/skills/bands)<a href="https://agentmods.dev/commands/artemnovichkov/skills/bands"><img src="https://agentmods.dev/badge/commands/artemnovichkov/skills/bands/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/artemnovichkov/skills/bands"><img src="https://agentmods.dev/badge/commands/artemnovichkov/skills/bands.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.00507 |
| Opus 5 | $0.00011 | $0.00253 |
| Sonnet 5 | $0.00004 | $0.00101 |
| Haiku 4.5 | $0.00002 | $0.00051 |
Grade A, and why
bands scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Stage 6 — Close the loop
Production signal becomes a new intent instead of a ticket someone notices on Monday. Detection stays deterministic; the model is only invoked once a band is breached.
Workflow
1. Pick one metric
Start with a single metric that already exists and already matters: CI failure rate, crash-free sessions, p95 latency, error rate. One metric wired end to end beats five half-wired.
Ask where it can be read from without new infrastructure — CI API, Crashlytics, an existing dashboard's API, a log query.
2. Define the bands
Write sdlc/bands.yaml from ${CLAUDE_PLUGIN_ROOT}/templates/bands.yaml:
- Baseline: a rolling window (30 days is a reasonable default)
1σ→ log only2σ→ invoke Claude read-only to diagnose (Read, Grep, and specific read-only Bash queries)3σ→ Claude may act, and only through pre-approved routes: open a pull request, or run a named runbook
Detection is arithmetic — mean and standard deviation, or Western Electric rules. Keep it in the watcher script, out of the model.
3. Write the watcher
A small script that reads the metric, compares against the baseline, and on breach invokes claude -p with the tier's tool restrictions. It runs on a schedule (cron, or a CI schedule). No production credentials; read-only tokens only.
4. Route the output
At tier 2 the diagnosis is written as sdlc/intent/<slug>.md in the stage 1 format — that is the loop closing. The user triages it like any other intent: small fixes go straight to /sdlc:plan, larger ones get a spec first.
At tier 3, action is bounded to a PR or a named runbook. Nothing merges or deploys without a human. Rehearse the rollback path before it is needed.
5. Prevent the repeat
When a fix ships, add an eval case for that incident class (/sdlc:evals). Repeat incidents of the same class are the metric that says whether this stage is working.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 42 lines · 22 tokens per session scan A a553922fbd30
bands is a command published in the GitHub repository artemnovichkov/skills (36 stars, last pushed yesterday), licensed MIT. It adds 22 tokens to every session and 507 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-07.
Other commands, from other repositories
k8s-manifest
Generate production-ready Kubernetes manifests for the current application.
configure-blob
Create and configure an Azure Blob Storage account with security best practices.
configure-gcs
Create and configure a GCS bucket with proper security settings.
setup-lambda
Configure and deploy an AWS Lambda function with proper settings.
update-status
Update the status and progress of Linear tickets.
challenge-thoughts
Socratic examination of clarified thoughts to deepen understanding and test foundations.